@mjg59@nondeterministic.computer
@mjg59@nondeterministic.computer avatar

mjg59

@mjg59@nondeterministic.computer

Former biologist. Actual PhD in genetics. Security at https://aurora.tech, OS security teaching at https://www.ischool.berkeley.edu. Blog: https://mjg59.dreamwidth.org. He/him.

This profile is from a federated server and may be incomplete. Browse more on the original instance.

mjg59, to random
@mjg59@nondeterministic.computer avatar

The FSF is considering appointing John Gilmore to their board? The same John Gilmore who invites people to parties and just fails to mention to them that there's LSD in the bottled water? https://www.fsf.org/news/the-fsf-board-candidate-discussions-will-start-on-may-29

mjg59,
@mjg59@nondeterministic.computer avatar

@Orca no

mjg59,
@mjg59@nondeterministic.computer avatar

@Orca (not everything that happens ends up documented online, sadly)

mjg59, to random
@mjg59@nondeterministic.computer avatar

Emeryville feels like an entirely made up place. 10% of the population lives above a shopping mall. Its primary industry is Pixar. There's a diner owned by the guy from Green Day. Trains from Chicago that are supposed to go to San Francisco terminate there instead. The primary tourist attraction is Ikea. This is all entirely implausible.

mjg59,
@mjg59@nondeterministic.computer avatar

@loke I actually kind of love it

mjg59, to random
@mjg59@nondeterministic.computer avatar
mjg59, to random
@mjg59@nondeterministic.computer avatar

"Why won't those mean Linux people let ZFS into the kernel" I dunno maybe it's because Sun released it under a GPL-incompatible license and Oracle could just fix that whenever they wanted by upgrading the license but hasn't?

mjg59,
@mjg59@nondeterministic.computer avatar

@penguin42 they can't relicense work they don't own, but they can release a new version of the CDDL and the default is for CDDLed work to pick up the new version automatically

mjg59, to random
@mjg59@nondeterministic.computer avatar

Why is there no browser API for local hardware-backed keys (Chrome has one for ChromeBooks, but it's still limited to force-installed enterprise managed extensions)

mjg59,
@mjg59@nondeterministic.computer avatar

Twitter just sticks encryption keys in browser local storage, which makes duplicating device identity trivial

mjg59,
@mjg59@nondeterministic.computer avatar

@stephenjudkins I'm more worried about the malicious application on the endpoint scenario - it's not a big deal on mobile, but on desktop there isn't a strong security barrier around the local storage

mjg59, to random
@mjg59@nondeterministic.computer avatar

Microsoft security update that blocks Black Lotus (and, incidentally, also blocks a lot of existing Windows boot media and recovery images - you do want to be careful in applying this, but I'm still kind of amazed this ended up being politically viable!) https://support.microsoft.com/en-us/topic/kb5025885-how-to-manage-the-windows-boot-manager-revocations-for-secure-boot-changes-associated-with-cve-2023-24932-41a975df-beb2-40c1-99a3-b3ff139f832d

mjg59,
@mjg59@nondeterministic.computer avatar

@Rairii dbx revocation is purely of old bootloaders, for any that support policy management for boot apps they've just added a policy that prohibits loading all old boot apps

mjg59, to random
@mjg59@nondeterministic.computer avatar

Is there any way to single-ticket book a train from London to small Spanish cities? trainline doesn't seem to believe a bunch of the Renfe services exist, and Renfe doesn't seem to ticket Eurostar.

mjg59,
@mjg59@nondeterministic.computer avatar

@michael Oh, thanks! For the journey I'm interested in it suggests taking Euskotren, which isn't bookable online but meh. I was expecting to be able to single-ticket via Barcelona or something.

mjg59, to random
@mjg59@nondeterministic.computer avatar
mjg59, to random
@mjg59@nondeterministic.computer avatar

Is there a writeup anywhere of how the Pixel phone migration stuff works? It clearly makes use of the D2D transfer stuff, but it's not obvious what actually triggers sending stuff over the wire.

mjg59, to random
@mjg59@nondeterministic.computer avatar

I wrote a moderately detailed description of what Twitter seems to be doing for encrypted DMs. tl;dr - better than unencrypted DMs, worse than Signal or WhatsApp. https://mjg59.dreamwidth.org/66791.html

mjg59, to random
@mjg59@nondeterministic.computer avatar
mjg59, to random
@mjg59@nondeterministic.computer avatar

You're all the sort of people who would have an idea about this, so: does anyone know where it's possible to find a copy of the ibcs2 patchset for Linux from the mid-90s? tsx-11.mit.edu appears long dead and I can't find a live mirror that has it.

(And no, I do not mean the ibcs2 support code in any of the BSDs, I am specifically talking about the patch to Linux that let you run SVR4 binaries)

mjg59, to random
@mjg59@nondeterministic.computer avatar

Good news my biggest concern about Twitter's e2ee DMs seems to be mitigated by only allowing a single device to be used for encrypted DMs at any given time, and warnings shown if the device ID or key changes.

mjg59,
@mjg59@nondeterministic.computer avatar

This is pretty awful UX but it does deal with the worst of the security concern (assuming people don't change devices too often, which would just inure people to this entirely)

mjg59,
@mjg59@nondeterministic.computer avatar

Anyway one outcome of this is that you can just hit an API endpoint with a Twitter user ID and find out how many devices they have registered and see when they add a new one

mjg59,
@mjg59@nondeterministic.computer avatar

(Elon has 4)

mjg59, to random
@mjg59@nondeterministic.computer avatar

Anyone with Android RE experience and some understanding of cryptography willing to verify what I've figured out about the Twitter e2ee implementation so far?

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • GTA5RPClips
  • DreamBathrooms
  • InstantRegret
  • magazineikmin
  • osvaldo12
  • Youngstown
  • ngwrru68w68
  • slotface
  • everett
  • rosin
  • thenastyranch
  • kavyap
  • tacticalgear
  • megavids
  • modclub
  • normalnudes
  • cubers
  • ethstaker
  • mdbf
  • Durango
  • khanakhh
  • tester
  • provamag3
  • cisconetworking
  • Leos
  • anitta
  • lostlight
  • All magazines